filefast.co.ukSign in
LGL-01 / PRIVACY_POLICY >>>//
Syncs App Ltd · Legal

Privacy Policy

Effective Operator Syncs App LtdCompany No. 15902605483 Green Lanes, London, England, N13 4BS

This policy explains what personal data filefast.co.uk collects when you use the service, why we collect it, who we share it with and what rights you have over it.

It is written in plain English on purpose. If anything is unclear, ask us — the address is at the end.

Who we are

The service at filefast.co.uk is operated by Syncs App Ltd, a company registered in England and Wales ("we", "us", "our"). For the purposes of UK data protection law — the UK GDPR and the Data Protection Act 2018 — we are the controller of the personal data described in this policy.

You can reach us about anything in this policy at syncs.bio@gmail.com, or by post at Syncs App Ltd, 483 Green Lanes, London, England, N13 4BS.

The data we collect

  • Account data — your email address, your name if you provide one, and your password, which we store only as a cryptographic hash. If you sign in through a third-party provider, we receive the identifiers that provider shares with us.
  • Company data — the company's name, Companies House registration number, Unique Taxpayer Reference (UTR) and accounting period dates.
  • Financial data — the accounts, ledgers, computations, adjustments and supporting documents you upload or enter to prepare a return. These may contain personal data about directors, employees or other individuals; you are responsible for having the right to share that data with us.
  • Filing data — the contents of returns you approve and submit, HMRC submission receipts and the identifiers needed to match them to your return.
  • Technical data — IP address, browser type, sign-in timestamps and server logs, kept for security and troubleshooting.
  • Usage data — which steps of the service you use and when, linked to your account; and, only if you accept analytics cookies, the pages you view and the links and buttons you click on our public website.

Where the data comes from

  • Directly from you, when you create an account, enter company details or upload documents.
  • From the public register at Companies House, when you look your company up inside the service.
  • From HMRC, when it acknowledges or responds to a submission made through the service.

How we use your data

UK GDPR requires a lawful basis for every use of personal data. Ours are:

  • Performance of a contract — running your account, preparing your return, submitting it to HMRC and keeping your filing history available to you.
  • Legal obligation — keeping the records that tax and accounting law requires us to keep, and responding to lawful requests from authorities.
  • Legitimate interests — securing the service, preventing fraud and abuse, diagnosing faults and improving how the service works, including measuring which parts of the service are used.
  • Consent — analytics cookies in your browser, and product and marketing email, each only if you opt in. You can withdraw consent at any time and it does not affect anything else in this policy.

Transactional email — password resets, email verification, submission receipts — is part of running the service, not marketing, and does not depend on any subscription.

Filing with HMRC

When you approve and submit a return, we transmit its contents — the CT600, the iXBRL accounts and computations, and the identifiers HMRC requires — to HM Revenue & Customs through its Corporation Tax online service. Nothing is sent to HMRC until you have reviewed the return and confirmed submission.

Once received, that data is held by HMRC as a separate, independent controller under its own rules. HMRC publishes its privacy information on GOV.UK.

Who we share data with

We do not sell personal data, and we do not share it for advertising.

  • Infrastructure providers that host the application and its database — currently cloud platforms such as Vercel and Railway.
  • Our transactional email provider, which delivers sign-in and filing emails on our behalf.
  • Our product analytics provider, PostHog, hosting data in the EU. It receives your account identifier, your email address and records of the actions you take in the service, and — only with your consent — website visits recorded by analytics cookies. It never receives your UTR, financial figures or uploaded documents.
  • Our payment processor, when you pay for a return — it receives what it needs to take the payment; we never see or store full card details.
  • Professional advisers and authorities, where the law requires disclosure or where it is necessary to establish or defend legal claims.

Every provider processes data under a contract that restricts it to acting on our instructions.

International transfers

Some of our providers process data outside the United Kingdom, including in the EEA and the United States. Where they do, the transfer is protected by UK adequacy regulations or by the International Data Transfer Agreement or Addendum approved under UK GDPR.

How long we keep data

  • Account and company data — for as long as your account is open.
  • Filed returns and their supporting data — for as long as your account is open, so your filing history stays available to you. Companies are required to keep Corporation Tax records for at least six years from the end of the accounting period; the service is designed to help with that, but the statutory duty remains yours.
  • Server logs — up to 12 months.
  • Product analytics records, including your email address — kept by our analytics provider, and not deleted automatically when you delete your account. Ask us and we will delete them.

When you delete your account:

  • your personal data — name, email address, password and any linked sign-in accounts — is erased straight away, and signing in becomes impossible;
  • companies you never filed for are deleted with the account, along with everything entered for them;
  • companies whose returns were filed with HMRC are kept, without any link to you as a person, for six years from the end of the accounting period of the last return filed. We keep them as evidence of what was submitted on the company’s behalf — a record we are required to be able to produce and may need to defend a claim;
  • once that period ends, those records are deleted automatically. Deletion runs weekly, so a record may remain for up to seven days after its retention period expires.

How we protect data

Data is encrypted in transit, passwords are stored only as hashes, and access to production systems is restricted and authenticated. Internal services talk to each other over authenticated channels, not the open internet.

No system is perfectly secure. If a breach ever affects your personal data, we will notify you and the Information Commissioner’s Office as the law requires.

Your rights

Under UK GDPR you can ask us to:

  • give you a copy of the personal data we hold about you (access);
  • correct data that is inaccurate or incomplete (rectification);
  • delete data we no longer have grounds to keep (erasure);
  • limit how we use it while a dispute is resolved (restriction);
  • hand your data over in a portable format (portability);
  • stop processing based on legitimate interests or consent (objection and withdrawal).

To exercise any of these, email syncs.bio@gmail.com. We respond within one month. If you are unhappy with our answer, you can complain to the Information Commissioner's Office at ico.org.uk — though we would appreciate the chance to sort it out first.

Cookies

Essential cookies keep you signed in and protect forms against cross-site request forgery. They cannot be switched off, because the service does not work without them.

A cookie named cookie-consent remembers your choice about analytics cookies for 180 days, so we do not ask on every visit. It is essential and holds nothing but that choice.

Analytics cookies are set by PostHog, our analytics provider, and are named ph_…_posthog. They let us count visits and see which pages and buttons are used, so we can improve the service. No analytics script loads and nothing is set until you accept; if you decline, none are set at all. Inside your signed-in account we record page views but not your clicks or what you type.

Analytics requests go through our own domain rather than straight to PostHog. That does not change what is collected or who receives it — only the address the request passes through. There are no advertising cookies and no cross-site tracking.

You can record your choice in advance on this page — the control sits at the end of this document — and change it at any time. Withdrawing is as easy as giving consent, takes effect immediately and removes the analytics cookies from your browser.

Changes to this policy

When this policy changes, the new version is published here with a new effective date. If a change materially affects how your data is handled, we will tell you by email before it takes effect.

How to contact us

Questions, requests and complaints about personal data all go to syncs.bio@gmail.com. Please mention "data protection" in the subject so it reaches the right person quickly.

If you would rather write to us, our postal address is Syncs App Ltd, 483 Green Lanes, London, England, N13 4BS.

Analytics cookies

You have not made a choice yet.